DoS vulnerability in Internet Explorer

Credit: MustLive
Risk: Medium
Local: No
Remote: Yes
CWE: CWE-Other

CVSS Base Score: 5/10
Impact Subscore: 2.9/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: None
Integrity impact: None
Availability impact: Partial

Not sure if this matters or not but it also worked on blackberry browser on blackberry 8800. Regards. ------Original Message------ From: MustLive To: bugtraq (at) securityfocus (dot) com [email concealed] Sent: Nov 8, 2009 8:54 AM Subject: DoS vulnerability in Internet Explorer Hello Bugtraq! I want to warn you about Denial of Service vulnerability in Internet Explorer. Yesterday I already informed Microsoft. This attack I called DoS via homepage. DoS: With this exploit in IE6 the browser blocks, so it's become impossible to use it and it's only possible to close it (via Task Manager). With this exploit in IE7 the browser freezes after click on the link . Vulnerable versions are Internet Explorer 6 (6.0.2900.2180), Internet Explorer 7 (7.0.6000.16711) and previous versions (and possible next versions too). I mentioned about this vulnerability at my site ( Best wishes & regards, MustLive Administrator of Websecurity web site Sent via BlackBerry from T-Mobile


